news details |
|
|
| Hackers On Prowl | | | The latest warning issued by the Indian Cyber Crime Coordination Centre (I4C) about hackers may target organisations using cPanel and WebHost Manager (WHM) systems has sent alarm bells ringing. The warning states that these attacks could result in unauthorised access, ransomware deployment, data theft and disruption of online services. The advisory, issued by the National Cybercrime Threat Analytics Unit (NCTAU) of I4C, urges users and system administrators to take immediate security measures to protect their hosting environments. According to the warning issued by the National Cybercrime Threat Analytics Unit (NCTAU) of I4C, attackers could exploit vulnerable hosting environments to gain unauthorised access, deploy ransomware, steal sensitive data and disrupt online services. Such attacks can have consequences far beyond temporary website outages. They can expose customer information, damage an organisation’s reputation, interrupt business operations and impose substantial financial costs. According to the advisory, compromised cPanel and WHM systems could provide attackers with unauthorised access to hosting management systems. Such access could potentially be exploited to deploy ransomware, steal sensitive information and disrupt websites and other online services. The I4C has advised citizens, organisations and website administrators to update cPanel and WHM systems to the latest patched versions as a priority. The warning is particularly significant because cPanel and WHM are widely used tools for managing web-hosting environments. Their popularity makes them attractive targets for cybercriminals. A single compromised hosting account or server can potentially provide attackers with an entry point into websites, databases, email systems and other connected resources. The advisory’s call for immediate security measures therefore deserves serious attention from both large organisations and smaller businesses. System administrators should ensure that cPanel, WHM and associated software are fully updated and that known vulnerabilities are promptly addressed. Strong, unique passwords and multi-factor authentication should be standard wherever available. Unnecessary services and accounts should be disabled, while access privileges should be limited to what users actually need. Organisations must also strengthen their monitoring and backup arrangements. Regularly reviewed backups, stored securely and separately from production systems, can be critical in limiting the damage caused by ransomware. Logs and system activity should be monitored for unusual behaviour, including unexpected account creation, suspicious login attempts or unexplained changes to files. Yet technology alone cannot solve the problem. Cybersecurity is ultimately an organisational responsibility. Employees, administrators and management must understand that phishing, stolen credentials and poor security practices can provide attackers with the opening they need. Regular awareness training and clear incident-response procedures should therefore accompany technical safeguards. |
|
|
|
|
|
|
|
|
|
|
|
|
| |
| |
|
|
|
|
 |
|
|